CWE-190
Integer Overflow or Wraparound
Description
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-92
CVEs mapped to this weakness (3,398)
page 48 of 170| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38618 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability… | ||
| CVE-2023-36916 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these… | ||
| CVE-2023-36915 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these… | ||
| CVE-2023-36864 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-35989 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-35057 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-35004 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2024 | An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | ||
| CVE-2023-35644 | Hig | 0.51 | 7.8 | 0.06 | Dec 12, 2023 | Windows Sysmain Service Elevation of Privilege Vulnerability | ||
| CVE-2023-35632 | Hig | 0.51 | 7.8 | 0.07 | Dec 12, 2023 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | ||
| CVE-2023-48409 | Hig | 0.51 | 7.8 | 0.00 | Dec 8, 2023 | In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed.… | ||
| CVE-2023-33018 | Hig | 0.51 | 7.8 | 0.00 | Dec 5, 2023 | Memory corruption while using the UIM diag command to get the operators name. | ||
| CVE-2023-4295 | Hig | 0.51 | 7.8 | 0.00 | Nov 7, 2023 | A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory. | ||
| CVE-2023-21375 | Hig | 0.51 | 7.8 | 0.00 | Oct 30, 2023 | In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-38127 | Hig | 0.51 | 7.8 | 0.01 | Oct 19, 2023 | An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An… | ||
| CVE-2023-36593 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | ||
| CVE-2023-43787 | Hig | 0.51 | 7.8 | 0.00 | Oct 10, 2023 | A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. | ||
| CVE-2023-38150 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-38142 | Hig | 0.51 | 7.8 | 0.07 | Sep 12, 2023 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2023-36792 | Hig | 0.51 | 7.8 | 0.01 | Sep 12, 2023 | Visual Studio Remote Code Execution Vulnerability | ||
| CVE-2023-4734 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. |
- risk 0.51cvss 7.8epss 0.00
Multiple integer overflow vulnerabilities exist in the VZT facgeometry parsing functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…
- risk 0.51cvss 7.8epss 0.00
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these…
- risk 0.51cvss 7.8epss 0.00
Multiple integer overflow vulnerabilities exist in the FST fstReaderIterBlocks2 chain_table allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these…
- risk 0.51cvss 7.8epss 0.00
An integer overflow vulnerability exists in the fstReaderIterBlocks2 temp_signal_value_buf allocation functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.00
An integer overflow vulnerability exists in the LXT2 zlib block allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.00
An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.00
An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
- risk 0.51cvss 7.8epss 0.06
Windows Sysmain Service Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.00
In gpu_pixel_handle_buffer_liveness_update_ioctl of private/google-modules/gpu/mali_kbase/mali_kbase_core_linux.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed.…
- risk 0.51cvss 7.8epss 0.00
Memory corruption while using the UIM diag command to get the operators name.
- risk 0.51cvss 7.8epss 0.00
A local non-privileged user can make improper GPU memory processing operations to gain access to already freed memory.
- risk 0.51cvss 7.8epss 0.00
In Sysproxy, there is a possible out of bounds write due to an integer underflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.01
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An…
- risk 0.51cvss 7.8epss 0.01
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
- risk 0.51cvss 7.8epss 0.01
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.07
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Visual Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.